We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-37863

ovl: don't allow datadir only



Description

In the Linux kernel, the following vulnerability has been resolved: ovl: don't allow datadir only In theory overlayfs could support upper layer directly referring to a data layer, but there's no current use case for this. Originally, when data-only layers were introduced, this wasn't allowed, only introduced by the "datadir+" feature, but without actually handling this case, resulting in an Oops. Fix by disallowing datadir without lowerdir.

Reserved 2025-04-16 | Published 2025-05-09 | Updated 2025-05-09 | Assigner Linux

Product status

Default status
unaffected

cc0918b3582c98f12cfb30bf7496496d14bff3e9 before 0874b629f65320778e7e3e206177770666d9db18
affected

24e16e385f2272b1a9df51337a5c32d28a29c7ad before b9e3579213ba648fa23f780e8d53e99011c62331
affected

24e16e385f2272b1a9df51337a5c32d28a29c7ad before 21d2ffb0e9838a175064c22f3a9de97d1f56f27d
affected

24e16e385f2272b1a9df51337a5c32d28a29c7ad before eb3a04a8516ee9b5174379306f94279fc90424c4
affected

Default status
affected

6.7
affected

Any version before 6.7
unaffected

6.6.88
unaffected

6.12.25
unaffected

6.14.4
unaffected

6.15-rc3
unaffected

References

git.kernel.org/...c/0874b629f65320778e7e3e206177770666d9db18

git.kernel.org/...c/b9e3579213ba648fa23f780e8d53e99011c62331

git.kernel.org/...c/21d2ffb0e9838a175064c22f3a9de97d1f56f27d

git.kernel.org/...c/eb3a04a8516ee9b5174379306f94279fc90424c4

cve.org (CVE-2025-37863)

nvd.nist.gov (CVE-2025-37863)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-37863

Support options

Helpdesk Chat, Email, Knowledgebase